Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

11–20 of 333 posts

Re: VPN location claims don't match real traffic exits

#11
I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Re: VPN location claims don't match real traffic exits

#12

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Same issue exists with Tor exit nodes. It’s anonymous in that you have a hoodie on with a giant spotlight right on you.

Re: VPN location claims don't match real traffic exits

#14

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

I wonder if using the wifi at a data center has the same broken browsing experience as using a VPN

Re: VPN location claims don't match real traffic exits

#15

I am not sure that I really understand what they did. I am also missing some major VPNs in the list. I currently use AirVPN but this has something to do with my use case and pricing. Why do you want to use a VPN? - Privacy - Anonymity (hint: don't!) - unblock geolocation - torrents - GFC The last point is the hardest. https://expatcircle.com/cms/privacy/vpn-services/

> I am not sure that I really understand what they did.

They checked where the VPN exit nodes are physically located. A lot of them are only setting a country in the whois data for the IP, but do not actually put the exit node in that country.

Re: VPN location claims don't match real traffic exits

#16

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Apple, for better or worse, has been able to use their size to pressure sites into accepting connections from their Private Relay service.

If VPN usage becomes the norm, sites will have to give in eventually.

Re: VPN location claims don't match real traffic exits

#17

I am not sure that I really understand what they did. I am also missing some major VPNs in the list. I currently use AirVPN but this has something to do with my use case and pricing. Why do you want to use a VPN? - Privacy - Anonymity (hint: don't!) - unblock geolocation - torrents - GFC The last point is the hardest. https://expatcircle.com/cms/privacy/vpn-services/

> I am not sure that I really understand what they did. They checked where the VPN exit nodes are physically located. A lot of them are only setting a country in the whois data for the IP, but do not actually put the exit node in that country.

Yes, I don't understand the advantage or disadvantage of this. Let's say I need a Colombian IP address, I would figure it out pretty quickly it this was not genuine, except if the geo-block protection would be fooled too.

Most of the "problem" countries are tiny places. Monaco, Andorra etc. It might be tough to rent a server there. And your list of clients should be minimal.

Re: VPN location claims don't match real traffic exits

#18

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

With CGNAT becoming more widespread, formats like this might need expansion to include location data for ports. Ie. Port 10,000-20,000 are consumers in New york, port numbers 20000-30000 are in Boston, etc.

Sounds awful, though. Maybe we should get more widespread usage for IPv6 instead.

Re: VPN location claims don't match real traffic exits

#19

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

Can really spot someone who has never had to deal with OFAC with a comment like this. Even if I don't necessarily agree with the concept, or who is actually being blocked, my business is dead in the water if I'm a) sent to prison or b) fined out of existence. Geographic IP information is one of our best tools to defend against those outcomes, and if anything it should be better.

If you were serious about limiting who uses your services you'd use an allowlist of ASNs. Even then, what about users using US-based residential proxies?

Re: VPN location claims don't match real traffic exits

#20

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Same issue exists with Tor exit nodes. It’s anonymous in that you have a hoodie on with a giant spotlight right on you.

A better metaphor would be that Tor and VPNs are like wearing a mask in public. It's obvious that you're trying to be anonymous, but you're still wearing a mask, so no one knows who you are.

You may be denied entry to certain establishments, but some of the bouncers don't block all masks and if you're persistent with changing your mask (Tor or VPN exit node), there's a good chance you'll get in. CTRL+SHIFT+L works on Tor Browser to change your circuit. The linked article blocks Tor, but after pressing CTRL+SHIFT+L a few times, I was able to read it.

For the sites that don't let me view them via Tor, I can install FoxyProxy and try some IPs from the free public lists. Lots of sites that block Tor don't block these IPs, although it's a bit of a pain. Another option is to load an archived version of the site on archive.org or archive.md (or .is or the various different TLDs it uses).

As for HN - it sometimes gives a "Sorry." if you try to access a certain comment directly, but after a few tries it works. This account was created over Tor and I've only accessed it through Tor. I think my first comment was dead and someone vouched for it, but now my comments appear instantly.

I've heard that banking sites don't work over Tor, but I haven't had a need to use Tor for banking, as the bank already knows who I am pretty well.

Most of the big social media sites don't allow Tor, but if I wanted to create a fake account, I'd most likely buy a residential proxy.

So it's not that bad, considering what you get from Tor (and with some VPNs, depending on your threat model) - no tracking, anonymity and so on.

Post reply on HN